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Sling v2 handles 
Java Web content 



BY ALEX HANDY 

Web development can bury a 
team under mountains of 
HTML files, images, and docu- 
ments from marketing and man- 
agement. Two years ago, as a 
way for Java developers to han- 
dle all that new "content," the 
Apache Sling project began. In 
May, the second, free release of 
this open-source Java Content 
Repository access framework 
was posted to the Apache Soft- 
ware Foundation's incubator 
website. 

This latest release includes 
bug fixes, expanded support for 
scripting languages and updates 
to keep in step with the OSGi 



specifiction, upon which Sling is 
based. The group hopes to have 
the first full release of Sling by 
the end of the year. 

Carsten Ziegeler, a commit- 
ter on the project, explained, 
"Without Sling, it is often very 
time-consuming to develop 
large websites with thousands of 
pages and even more content 
snippets displayed throughout 
the site. 

"Sling uses a Java Content 
Repository (JCR) as the back-end 
store for all information. One of 
the major goals is to have a modu- 
lar, scalable, extensible and flexi- 
ble platform, which is also man- 
continued on page 18 ► 



VS Team System gets 
new security template 




Now devs can secure their projects 
without being experts, says Ladd. 



BY DAVID WORTHINGTON 

Microsoft is attempting to demys- 
tify its Security Development 
Lifecycle by transforming it from 
a written process into a template 
for automation in Visual Studio 
Team System 2008. 

The SDL is a mandatory 
process used internally at Micro- 
soft during the development of its 
products, and Microsoft began to 
share its SDL expertise and tool- 
ing with customers last year to 
help secure applications further 
down the Windows stack. 

A free download called the 
SDL Process Template became 
available in May on Microsoft's 



MSDN website. Microsoft is also 
working toward a release of the 
template for Visual Studio 2010. 

Microsoft's objective is to help 
developers bootstrap internal 
security efforts, said David Ladd, 
principal security program man- 
ager of Microsoft's SDL team. 

Ladd's team also announced 
an expansion of the SDL Pro 
Network, a pilot program that 
trains security experts in tools 
and guidance associated with 
the SDL. The new participants 
are from Science Applications 
International Corp., a U.S. gov- 
ernment contractor for cyber 
continued on page 18 ► 



Parallelism, privacy on TechEd plate 



BY DAVID WORTHINGTON 

LOS ANGELES — TechEd has 
been a venue for Microsoft to 
make big product and platform 
announcements, but it is ^^^ 
ultimately a place where 
developers come to learn. 
Two sessions — on data 
privacy and multicore ^^^ 
programming — were especially 
popular with attendees. 

The broad availability of many- 
core processors is changing appli- 
cation architecture, but parallel 
programming remains challenging 
for many developers, Microsoft 
said. In a session titled "The Many- 
core Shift: Making Parallel Corn- 



Mainstream," Stephen 
program manager 



puting 

Toub, senior 

lead for parallel computing plat 

forms at Microsoft, explained how 

^^^^^^ m Microsoft would ease the 

TECHED transition to concurrency. 
SHOW 

"Moore's Law is not 

REPORT 

PAGE 12 dead," he said, but power 

consumption 



dramatically with even modest 
gains in clock speed. Given that 
challenge, additional computing 
power is being supplied by 
adding cores to processors, and 
mainstream machines will soon 
have as many as 24-120 cores, he 
added. 

Developers have had a "free 



lunch" when writing applications 
for years, and they were always 
able to count on faster processors 
to speed up their applications, he 
said. However, that free lunch is 
over unless parallel program- 
ming becomes easier to do, Toub 
said. "We want to get back the 
free lunch." 

Other benefits of parallelism 
include the ability to offload 
work, processing more data in 
the allotted time, and doing 
speculation (a programming 
technique to improve perfor- 
mance), he said. 

However, companies have few 
continued on page 15 ► 
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Google places bet on HTML 5 r Java 



BY ALEX HANDY 

The future of Google will be 
built on HTML 5 and Java. 

This was the message deliv- 
ered by Vic Gundotra, Google's 
vice president of developer 
platforms, at the Google I/O 
Conference for developers, in 
late May in San Francisco. 

For many Java developers, 
Google Web Toolkit (GWT) has 
provided a bridge to Web appli- 
cation development. GWT 
translates Java code into 
JavaScript, and Google has 
used it internally to produce 
desktop-like applications, such 
as Google Maps. 

Gundotra, in his keynote 
speech at the conference, intro- 
duced Google Web Elements, a 
simplified way to embed 
Google-hosted elements inside 
Web pages. 

At the top of Google's plans 
for developers is the road map 
for GWT 2.0. This next-genera- 
tion bridge between Java and 



JavaScript is already shaping up 
to address developer worries 
around compilation speed and 
graphical layout. 

Bruce Johnson, software 
engineer and GWT tech lead at 
Google, spoke about the GWT 
road map immediately follow- 
ing Gundotra's keynote. Of the 
changes planned for GWT 2.0, 
he said that the in-browser 
hosted mode would see the 
most dramatic changes. This 
mode, primarily used for 
debugging, would soon be 
revamped with browser plug- 
ins to help developers support 
more than one browser in each 
OS, said Johnson. 

"It gives you the ability to 
debug in Java, make a change in 
your source code, and hit 
refresh in your browser to see 
the changes. This is not a simu- 
lation of a browser, it is a brows- 
er. We just had to wire it into 
the JVM. [Before 2.0], we're 
only able to make that happen 




A life-size Google Maps marker locates Google's I/O conference, where the 
company highlighted its APIs, including those from its mapping services. 



for one browser per OS." 

Johnson said that GWT 2.0 
will include in-browser hosted 
mode for all browsers, not just 
one per platform. In addition, 
he said that this new model for 
debugging would allow a devel- 
oper using Eclipse in the Mac 



OS to debug using a virtualized 
instance of Windows running 
Internet Explorer. 

Johnson also said that GWT 
2.0 will include compiler flags 
that can be used to speed up 
build times. He regretted the 
fact that 2.0 compile times were 



growing beyond what even he 
admitted were already long 
periods, but he also said that 
new compiler flags in GWT 2.0 
will make quick development 
builds faster. 

Beyond GWT 2.0, Johnson 
said that longer-term plans 
include the integration of the 
jQuery port, QuickQuery. 

As for Google's long-term 
platform plans, the company 
announced that support for Java 
within Google's cloud-like App 
Engine was no longer in beta 
form, but would now support 
Java at promised service levels. 
Also, the company will begin uti- 
lizing features of HTML 5 with- 
in its applications, and it will 
offer similar support to develop- 
ers using their APIs. 

Gundotra said that HTML 
5's Canvas tag will improve lay- 
out control, and he predicted 
that its geolocation features and 
its video controls would ease 
life for developers. I 



COBOL anniversary celebrates a vibrant ecosystem 



BY ALEX HANDY 

A language can accrue a lot of 
capabilities over a 50-year peri- 
od. That's not exactly a common 
occurrence in software develop- 
ment: Few language have been 
around that long, 
let alone remained 
in common use. 
But COBOL's place 
in the enterprise 
and on the main- 
frames of business- 
es around the world 
remains a function of the lan- 
guage's ever-expanding hori- 
zons. 

Retired COBOL program- 
mer Jan Stuart worked with the 
language in many financial insti- 
tutions across her career. She 
said that COBOL's strength is its 
simple grammar, but that its 
longevity comes from add-ons. 

"I think COBOL does it all," 
said Stuart. "It's only got a 
dozen separate statements, but 
it actually does it all. What I 
have seen is that add-ons have 
been built around the edges, so 
I think in the 70s or 80s it was 
developed so you could com- 
municate with a DB2 database. 
Extra things have been added 
on so it can communicate with 
whatever the new platforms are. 
The core language that moves 




data and tests values and com- 
putes results hasn't changed, 
and I don't think it needs [to be 
changed]." 

Drake Coker, chief technolo- 
gist for application development 
at Micro Focus, said 
that, presently, his 
company finds a lot 
of work with mid- 
tier companies look- 
ing to move a 
COBOL application 
off of an old desktop 
Unix machine. 

"COBOL is available on vir- 
tually every platform," said Cok- 
er. "It remains true that the vast 
majority of COBOL programs 
run on IBM mainframes. That is 
the dominant aspect of COBOL. 
That being said, it is absolutely 
present in the Microsoft world, 
the Linux world and the off- 
brand Unix world. 

"The other big influence is 
the minicomputer legacy. In the 
80s, there was quite a bit of new 
software developed for things 
like VAXen and early Unix boxes 
that were small office applica- 
tions or vertical applications. 
Those tend to be developed in a 
lot of different languages, and 
COBOL was one of them. We 
have a good chunk of business 
that is that type of user." 



COBOL AT WORK 

Franz Ablinger, another retired 
COBOL programmer, wrote to 
SD Times that COBOL's strict 
command set is tailor-made for 
enterprises, and that this is one 
of the reasons the language con- 
tinues to be used after 50 years. 

"The nice thing with the 
COBOL language is that you 
can give out coding guidelines 
that keep the code static, using 
very strict rules," he said. "Most 
very large COBOL projects 
have done so to keep mainte- 
nance costs low. The company I 
worked for made use of this 
restriction. We developed soft- 
ware for automating COBOL 
code maintenance and migra- 
tion projects." 

Ablinger described one of 
the last projects he worked on 
as an example of how COBOL 
can live on in a modern work 
environment, even when other 
legacy software can't. 

In 2000, Ablinger was 
brought onto a team charged 
with modernizing the software 
that ran the Swiss National 
Accident Insurance Fund. That 
company's applications were 
hosted on OS/2 and ran fat 
clients written in COBOL that 
talked to a DB2 server on an 



IBM mainframe. The project 
took two years and managed to 
remove OS/2 from the puzzle, 
but the COBOL lived on within 
the stack. 

"The goal — to keep the 20 
years investment of legacy 
code, transform it into a service 
layer and migrate it to a Unix 
server farm, acting as a back 
end for a thin Java client — was 
fully reached. I heard that the 
back-end system is still in use, 
but the Java front end changed 
over the years," said Ablinger. 

Ablinger said that the system 
was capable of handling 2 mil- 
lion database hits in an hour, a 
testament to COBOL's ability to 
keep up, even in a modern Java 
environment. 

OPEN COBOL, OPEN FUTURE 

The popular open-source 
repository, SourceForge, hosts 
thousands of projects in C, Java 
and the various scripting lan- 
guages. But it also holds almost 
57 COBOL projects. These 
range from the largely com- 
plete "COBOL copybook to 
XML converter" project, to the 
still-evolving "COBOL and 
RPG data reader and convert- 
er". The focus of most such 
open-source projects are to give 
COBOL access to modern 



infrastructure and datasets. 

There are even some open- 
source projects being executed 
in COBOL just for fun, such as 
the simply named "Code Com- 
piler," an effort begun in 2007 to 
write a COBOL compiler writ- 
ten in COBOL. More recently, 
work began in March on the 
"Run COBOL Anywhere" pro- 
ject, another open-source effort 
to build a functional COBOL 
compiler that translates into Java 
or bypasses the language and 
compiles to bytecode. 

But the most popular open- 
source COBOL project is 
OpenCOBOL. This open- 
source compiler translates 
COBOL programs into C code 
so that they can be compiled 
using GCC. Doing so effective- 
ly makes COBOL a viable lan- 
guage in Linux and the BSD 
operating systems, breathing 
new life into old code. 

For Microsoft shops, Coker 
said that Micro Focus is 
focused on making COBOL 
work with .NET While the 
Web still holds some difficulties 
for COBOL, primarily because 
technologies move so quickly 
there, Coker said that integrat- 
ing COBOL is still necessary 
for many businesses with legacy 
applications. I 
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, COMPANIES , 



Scanning software provider GoScan will offer free versions of its 
scanners to all school districts in California for use on paper doc- 
uments. GoScan executives said GoScan can be used for convert- 
ing paper documents into electronic data for storage. 



, NEW PRODUCTS , 



Open-source database management company Ingres has created 
the Ingres Development Stack for JBoss, a preassembled bun- 
dle that lets developers use Red Hat's JBoss Developer Studio to 
create business applications that have database features. Some 
of those features include security auditing, database partitioning 
and high-availability clusters that offer failover by restarting 
applications on a redundant computer system if there are soft- 
ware faults . . . Mobile phone software provider Open Kernel Labs 
has created a virtualized version of the Symbian smartphone 
development platform called OK:Symbian. OK:Symbian lets 
developers run multiple mobile operating systems or multiple 
instances of the Symbian platform on a single device, according 
to Open Kernel Labs executives ... In the midst of its acquisition 
by Micro Focus, Borland Software has created a simulator for 
business analysts to put software project concepts into story- 
board format. Team Define lets users drag and drop screen ele- 
ments, as well as assemble connections to data and logic from 
customers, Borland executive said. 



, UPDATES , 



Web performance management company Coradiant is incorpo- 
rating dynaTrace Software's application performance manage- 
ment technology into its products. Coradiant executives said 
this integration helps to link end-user performance issues with 
the underlying application code responsible for causing prob- 
lems . . . Salesforce.com has released a new version of 
Force.com for Google App Engine, which provides services 
to build Web and business applications entirely in cloud com- 
puting environments. Salesforce executives said the new ver- 
sion offers Java libraries designed to run on Google App Engine, 
allowing App Engine applications to read and write to Force.com 
using the Force.com SOAP API . . . Architecture management 
company Lattix has added integration with IBM's Telelogic 
Rhapsody model-driven development environment in the latest 
version of its Lattix software architecture manager. Lattix 5.0 
also includes 10 different partitioning algorithms for analyzing 
and re-architecting a system . . . Mobile device component 
company Resco has added three new components to Mobile- 
Forms Toolkit 2009 Volume 2. AdvancedCombo for .NET 
allows developers to use templates and pictures. The Numeric- 
UpDown for .NET component allows for the use of decimal 
and hexadecimal numbers when collecting data, Resco execu- 
tives said. Lastly, the TouchDateTimePicker for .NET is a con- 
trol for setting the time and date in a mobile application 
. . . Data visualization component provider Nevron Software 
has released an update to its .NET Vision component suite 
for WinForms and ASP.NET development. .NET Vision 2009 
Vol. 1 has new 2D and 3D display features, as well as improve- 
ments to chart axes, including the ability to specify an axis 
range. Additionally, a new knob indicator lets users modify data 
values . . . Elementool, a provider of Web-based project man- 
agement software, has released a new version of its Test Case 
project manager. Test Case 1.1 has the ability to attach files to 
test cases in order to clarify instructions and steps in tests, 
according to Elementool. Additionally, there is a new message 
board for project team members and a customizable test form 
that lets administrators to add fields to a test form. I 



Call it the 'gotcha' mashup 

Vi Labs uses Google Maps to pinpoint pirates 



BY JEFF FEINMAN 

Security provider Vi 
Labs is putting piracy 
on the map by mashing 
up its database with 
Google Maps. 

The company re- 
leased in May a new 
version of its CodeAr- 
mor Intelligence soft- 
ware anti-piracy plat- 
form. CodeArmor 
Intelligence can now 
report piracy by col- 
lecting data at a gate- 
way server, according 
to company executives. 
Geographic informa- 
tion is then added to 
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CodeArmor Intelligence users can view where 

piracy infringements are coming from, as the platform mixes its reporting capabilities 
the platform, and users with geographic information displayed through Google Maps. 

can view the location of 



the infringing party through 
Google Maps. 

Users can see how many 
infringements are being report- 
ed from a regional perspective. 
Web services then add business 
profile information and an 
organization's latitude and lon- 
gitude from its IP address. 
Users can zoom in to a street- 
level view of the reportedly 
pirated software, Vi Labs exec- 
utives said. 

"We present to the client an 



interface that says, 'Click here to 
see where this falls within Google 
Maps,'" said Victor DeMarines, 
vice president of products for Vi 
Labs. "So all the data is coming 
from the infringements that we're 
detecting in the field, and then 
we can augment that data with 
other Web services, and in the 
end, you're going to see this non- 
compliant organization through a 
screenshot." 

DeMarines said Vi Labs' 
clients have direct access to the 



data, and the clients can deter- 
mine how to follow up on that 
information. 

CodeArmor Intelligence is 
priced at an annual subscription 
fee starting at US$50,000. 

Other new features in the 
release include rules-based fil- 
tering and an improved SDK 
that now provides sample appli- 
cations that Vi Labs said could 
simplify integrating CodeAr- 
mor Intelligence into third-par- 
ty applications. I 



Intel focuses on concurrency 



BY DAVID WORTHINGTON 

Intel is "solidly convinced" that 
its Parallel Studio development 
suite will enable organizations 
to deliver parallel programs on 
schedule by addressing the 
unique development life cycle, 
said James Reinders, chief 
product evangelist and director 
of marketing for Intel's software 
development products division. 

Parallel Studio became gen- 
erally available in May. It con- 
sists of Parallel Advisor, Parallel 
Composer, Parallel Inspector 
and Parallel Amplifier, as well 
as compilers and libraries for C 
and C++ programs. 

Most significantly, said Rein- 
ders, the suite helps developers 
root out errors in deterministic 
programs, a style of program- 
ming where instructions are 
carried out consistently every 
time a program is executed, he 
explained. 

Determinism helps avoid 
conflicts when the components 
of a parallel program are run- 



ning concurrently, such as data 
race conditions and dead- 
locks — types of data processing 
errors that can cause programs 
to crash and lose data. 

Intel Parallel Advisor exam- 
ines source code to advise 
developers about where they 
can apply parallel programming 
to their application. It also 
makes recommendations on 
how to implement the threads, 
and it identifies potential con- 
flicts and ways resolve them. 

"We don't want people to 
think that the compiler solves 
the problem of moving to paral- 
lelism," said Reinders. "It 
requires an architect to think 
about introducing parallelism 
into a program. They prototype, 
try it out. . .It may or may not be 
a dead end, and could take 
weeks or months." 

Parallel Advisor accelerates 
that process, eliminating the 
need for prototyping, he 
explained. It selects places 
where parallelism can be added 



to a program, and it models to 
determine whether the code 
will scale, he said. 

A beta of Parallel Advisor is 
shipping with Parallel Studio; 
the final edition will be deliv- 
ered before the end of the year. 

Parallel Composer provides 
a compiler and libraries for 
Microsoft Visual Studio. APIs 
and components, including the 
OpenMP 3.0API specification, 
Intel Threading Building 
Blocks, and Intel Integrated 
Performance Primitives, raise 
the level of abstraction from 
low-level thread management. 

Parallel Inspector is a 
dynamic analysis tool that is 
based upon Intel Thread 
Checker, the company's solu- 
tion for creating code that is 
"parallel safe." 

Lastly, Intel Parallel Amplifi- 
er is designed to help users 
locate multicore performance 
bottlenecks, such as unexpected 
serialization. It is designed for 
non-experts. I 
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In a Flash, Adobe spices up its IDE 



BY JEFF FEINMAN 

After releasing Flash Player 10 
last fall, Adobe Systems is 
adding summertime spark to 
some key components of the 
Flash platform. 

The Flex Builder Eclipse- 
based IDE has been rebranded 
as Flash Builder in order to dif- 
ferentiate the open-source Flex 
framework and the commer- 
cially available Builder IDE. 
The name Flex will only refer to 
the open-source Flex frame- 
work. Adobe executives said 
that the Builder brand was 
brought under the Flash 
umbrella because much of the 
Flash Builder user base consists 
of ActionS cript developers who 
are developing Flash content, 
not Flex applications. 

"Since we introduced Flex, 
there's always been the Flex 
framework and Flex Builder," 
said Dave Gruber, group prod- 
uct marketing manager at 
Adobe. "There's been a fair 
amount of confusion for people 
saying, Ts that open source?' 
There's been confusion about 
what Flex is, so we're trying to 
clean that up." 

One thing that Adobe is try- 
ing to do around Flash is to 
increase productivity for devel- 
opers and end users. Flash 
Builder 4, expected to be 
announced on June 1, comes 
with interactive visual editing 
capabilities for Adobe's Action- 
Script and MXML user interface 
markup language. There are also 
new debugging and memory 
profiling features. 

Additionally, Flash Builder 
has a new service integration 
wizard, and there are also new 
user interface form generators 
and drag-and-drop capabilities 
for user interface components. 

In Flash Builder, Adobe has 
tried to improve day-to-day 
coding tasks with new features 
around code templating, for- 
matting and improved code 
refactoring, said Tim Buntel, 
senior product manager with 
Adobe. Additionally, code gen- 
eration behind common events 
and buttons associated with UI 
objects is handled automatical- 
ly. There is also a new feature 
for unit testing that both runs 
and generates tests. 

Buntel said Adobe expects 
Flash developers to utilize the 
Flash codebase. "This isn't a 
WYSIWYG application experi- 
ence," Buntel said. "The design 



view is really good for laying out 
the component and wiring 
them up together, but then typ- 
ically you will go into code view. 
This is a full, functional, profes- 
sional IDE, so these are coders 



that should be comfortable with 
that." 

Buntel added that Builder 
has always been targeted 
toward traditional application 
developers, but some of the 



new coding features make it 
easier for Web developers to 
create apps using the tool. 

Beyond the update of Flash 
Builder, Adobe has also intro- 
duced the public beta of Flash 



Catalyst, an interface designer 
for rapidly creating application 
interfaces and interactive con- 
tent without coding. Gruber said 
Flash Catalyst targets application 
user interface designers, and it 
lets designers create and assem- 
ble user interface assets. 

Flash Catalyst was previous- 
ly codenamed Thermo. I 
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Atlassian acquires 
agile tools for J IRA 



BY ALEX HANDY 

If you're averse to paper cuts, Atlassian 
has an agile solution for you. The com- 
pany acquired GreenPepper Softwares 
GreenHopper project management 
plug-in for Atlassian s JIRA issue-track- 
ing software. GreenHopper is essential- 
ly a set of index cards virtualized and 
pasted into the Web interface of JIRA 
Studio. Those cards help manage tasks 
and to-do lists, and feature sets for agile 
software development projects. 

Daniel Freeman, director of product 
marketing at Atlassian, said that these 
cards can be organized, annotated and 
modified in the same ways normal index 
cards can. 

"It turns your issues, tasks and story 
points in JIRA into cards," he said. "You 
have a planning board that allows you to 
have multiple different versions and get 
a view of where your cards are for each 
version. You'll start with a backlog view, 
then you'll drag and drop which cards 
you want to go into which iteration." 

Freeman said that GreenHopper is 
included with JIRA Studio's US$25 per- 
user per-month price tag. As a hosted ser- 
vice, it requires no installation on site. For 
users of existing Atlassian software, how- 
ever, GreenHopper can be added for 
$350. With the acquisition of this intellec- 
tual property, and the two developers 
behind it, Atlassian brings billing and sup- 
port for the plug-in under its own roof. 

For distributed agile teams, said Free- 



man, GreenHopper includes many ways 
to differentiate one card from another. 

"Each card is color-coded, and there 
is a task board," he said. "It's about man- 
aging these cards once you've selected 
them for a different iteration. There are 
to-do lists and in-progress stuff, and one 
of our teams has created a separate cus- 
tom field called in-review, for items that 
are in code review. What's really nice 
here about agile teams is that you're able 
to drag and drop the cards from differ- 
ent status points, and let's say you're in 
progress but haven't completed it. You 
can say, T've done five hours on this and 
it's not complete,' and leave it." 

Of course, it wouldn't be agile with- 
out charting. Freeman said that Green- 
Hopper "enables you to have burn-down 
charts and burn-up charts. You can do 
the charts based on milestones. It has 
good agile reporting. In a nutshell, 
GreenHopper is in the cards, planning 
board, task board and chart board." 

Atlassian provides integrations for 
GreenHopper though JIRA Studio with 
the company's Bamboo continuous inte- 
gration software, the Fisheye code 
repository manager, the Crucible code 
review tool and the company's Conflu- 
ence enterprise wiki. JIRA Studio also 
sports a Facebook-style activity screen, 
which allows developers to post screen- 
shots of projects and for others to com- 
ment on them to foster a more collabo- 
rative environment, Freeman said. I 



Talend: Data processing on steroids 

New MPX integration suite breaks down complex problems 



BY DAVID RUBINSTEIN 

Organizations can't help but accumulate 
mountains of data. Yet that data only has 
value if you can find the value it con- 
tains. To do that requires heavy-duty 
data processing and crunching. 

Open-source data integration com- 
pany Talend has released Integration 
Suite MPX, which extends its commer- 
cial offering to address this need to 
process extremely large amounts of 
data. The solution, released in May, now 
includes what the company is calling 
File Scale technology, and the ability to 
do massively parallelized processing. 

The FileScale technology is based on 
the MapReduce technology created by 
Google, according to Yves de Montcheuil, 
Talend's vice president of marketing. It is 
what lets Google process billions of Web 
pages for indexing and ranking purposes. 

"The technology lets us break down 
complex problems into smaller prob- 
lems. Then we can get multiple nodes 
process those problems," and it all gets 
built back up automatically by a main 
node, de Montcheuil explained. 



FileScale has low-level components that 
are optimized for such tasks as sorting, 
filtering and merging, aggregating, and 
transforming. FileScale will distribute 
these tasks to where resources are avail- 
able on the hardware, ensuring faster 
processing time, he said. 

When the problems are broken down 
into smaller subsets, they can be 
processed in parallel, simultaneously, 
and then automatically synched back up 
after the processing is complete, de 
Montcheuil said. He cited a benchmark 
using industry-standard TPC-H data 
sets that was run on a Sun Blade X6270 
server featuring two Intel Xeon 5520 
quad-core processors — "admittedly a 
high-end system but a real one, not 
something cobbled together just for a 
benchmark," he said. 

In-memory data sorting reached one 
million records per second, while 3.3 
billion records were sorted through at a 
speed of 200,000 to 400,000 per sec- 
ond. "That is a level of scalability that 
hasn't been reached before," de 
Montcheuil said. I 
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Innovation takes 
stage at Tech Ed 



BY DAVID WORTHINGTON 

LOS ANGELES — May's TechEd 
2009, held at the convention center 
here, was lined with booths representing 
some of the worlds largest software 
makers, as well as some entrepreneurs 
who braved the economic downturn. 

With the worldwide finan- 
cial crisis as a backdrop for the 
show, Altova demonstrated SHOW 
an XBRL (extensible Busi- 
ness Reporting Language) workflow that 
it says will help organizations provide 
investors greater transparency XBRL is 
a new standard for financial reporting. 

Altova demonstrated an XBRL docu- 
ment being generated from financial data 
using the company's MapForce data 
mapping tool; the XBRL taxonomy was 
extended using XMLSpy; and its StyleVi- 
sion visual stylesheet designer was used 
to generate custom financial reports. 

Converter Technology released 
OfficeConverter 9.4, an update to its 
Microsoft Office file conversation suite 



SDTimes 



that now supports PowerPoint files. 
"Organizations will know what docu- 
ments require remediation," said Shawn 
Allaway, vice president of sales and 
operations. 

Java and .NET component maker 
Infragistics showed off its Silverlight 3 

line of business controls. 

Highlights included support 
I for large data sets in its data 

grid control, as well as over 30 
different customer charts. The controls 
will be ready to ship within 30 days after 
Microsoft releases Silverlight 3 to manu- 
facturing this year, said lead technical 
evangelist Tony Lombardo. 

Interoperability tool developer 
JNB ridge announced JNBridgePro 4.1. 
JNBridgePro can generate Windows 
Presentation Foundation proxies from 
Java code through a process-generation 
tool that finds classes and methods, said 
CTO Wayne Citrin. The company is 
examining Silverlight support as a next 
step, he added. 
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Infragistics' NetAdvantage for Silverlight 
controls can add rich media effects to 
existing ASP.NET applications. 

Novell's Mono team was on hand to 
demonstrate a Visual Studio plug-in for 
Mono code development. Applications 
are deployed and debugged in Mono by 
using a Linux virtual machine. The 
company also previewed Mono Moon- 
light 2.0, an open-source variation of 
Microsoft Silverlight 2. 

PreEmptive Solutions used the 
occasion to introduce a low-end offer- 
ing of its .NET code instrumentation 
software called Dotfuscator Micro 
Developer Edition. Code instrumenta- 
tion offers valuable runtime intelli- 
gence about how applications are used, 
said chief marketing officer Sebastian 
Hoist. 

When Microsoft adds new features 
to SQL Server, it does not always pro- 
vide an interface. Quest Software 
announced that an interface for SQL 
Server 2008 extended events, which 
captures detailed information from 
the database engine, is now included in 
its Spotlight database performance 
profiler. 

Quest also announced a differential 
capability for its Lite Speed database 
backup utility. Backups go from being 
hours to minutes and comprise a single 
file, instead of being broken up into sec- 
tions, the company says. 

Distributed caching infrastructure 
maker ScaleOut Software announced 
ScaleOut StateServer 4.1. StateServer 
now allows customers to more intri- 
cately manage their caches by search- 
ing for session IDs in e-commerce 
applications, gaining real-time business 
intelligence, said William Bain, 
founder and CEO. "If a bunch of peo- 
ple are still shopping a sale, that sale 
may be extended for an hour," he 
explained. 

StateServer 4.1 also provides backing 
store support, allowing users to move 
items in and out of the cache to a data- 
base as desired. Improvements were 
also made to its load-balancing engine. 

ScriptLogic released a new version 
of its support ticket tracking system, 
Help Desk Authority 8.1, that integrates 
with the ScriptLogic s Desktop Authori- 
ty desktop management solution for 
asset tracking, patch management and 
problem resolution. I 



AMD, Microsoft 
join forces 
for Windows 
virtualization 



BY DAVID WORTHINGTON 

LOS ANGELES — AMD and 

Microsoft are working together to 
improve the performance of virtualized 
Windows applications. 

Microsoft has had input into the 
development of AMD's upcoming 
"Istanbul" processor, which is due to 
ship this month. AMD says that Istan- 
bul, a six-core processor, will provide 
near-native virtualization performance 
with better memory and I/O perfor- 
mance than earlier chips. The processor 
uses Rapid Virtualization Indexing (RVI) 
technology for memory management. 

The companies had worked closely as 
AMD developed RVI, which manages 
memory for hypervisors at the hardware 
level, said Jeff Woolsey, principal program 
manager in Windows Server for Hyper-V 
at Microsoft, in an interview at last month's 
Microsoft TechEd. RVI was added to 
AMD's Opteron processors in 2007. 

Prior to that, Microsoft's hypervisor 
had to govern physical memory address 
space for virtual machines, he explained. 
"Now we shunt that work down to the 
processor; it frees up megabytes of 
memory." 

AMD and Microsoft began to co- 
develop virtualization technology before 
AMD announced its "Pacifica" genera- 
tion of hardware in 2005, said Margaret 
Lewis, director of commercial solutions 
at AMD. Pacifica was the code name for 
the virtualization extensions that have 
resided in its hardware since 2006. 

Several years ago, AMD's 64-bit 
Opteron processor took Hyper-V devel- 
opment to a new level by helping to take 
64-bit computing into the mainstream, 
said Woolsey. 

Work is also ongoing with Microsoft's 
Windows Server product team. Microsoft 
Windows Server 2008 was the first oper- 
ating system to have default support for 
AMD PowerNow, a system for advanced 
server power management, she noted. 

"Our main design goal for virtualiza- 
tion is to reach near-native application 
performance. Microsoft talks about the 
same thing with [Windows] user experi- 
ence," Lewis said. 

"Virtualization has the muscle to 
drive any kind of workload. As we 
mature and develop it, it should 
become a standard part of anybody's 
infrastructure," she said. I 
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Parallelism, privacy stand out at TechEd 



< continued from page 1 

people who understand how to 
write parallel code, and that is a 
risk, Toub said. "It becomes 
instant legacy if they leave, with 
no one to maintain it." 

When he asked the audience 
how many wrote parallel code, 
a large number of attendees 
raised their hands; however, 
only three kept their hands 
raised when he asked if they 
thought it was easier to do. 

Toub then highlighted tech- 
nologies that Microsoft is provid- 
ing to smooth the way forward. 
The first technology he dis- 
cussed is Parallel Language Inte- 
grated Query (PLINQ), a con- 
current query execution engine 
for LINQ. He also mentioned 
several other technologies that 
will be included in Visual Studio 
2010 and Windows 7. 

PLINQ lets developers 
strategically change LINQ 
queries where parallel sorts 
make sense, he said. Microsoft 
made PLINQ optional for 



developers, because sequential 
queries are sometimes a better 
solution, he said. 

Visual Studio 2010 will 
include programming models, 
tools and runtimes to assist with 
parallel programming. Micro- 
soft added a concurrency profil- 
er that maps out thread execu- 
tion data to give developers a 
sense of how a program is exe- 
cuting, he said. 

Lastly, Windows 7 will have 
a native stack called User Mode 
Scheduler (UMS) that lets user- 
mode applications make deci- 
sions about what to run next, he 
said. 

NAVIGATING REGULATION 

A session called "Data Gover- 
nance: A Solution to Privacy 
Issues" covered a wide variety of 
issues that organizations must 
understand to stay on top of the 
rules and regulations that affect 
how they collect, store and use 
data. The low cost of storage has 
led to an unprecedented volume 



of data stored about individuals, 
and security alone is not enough 
to guarantee privacy, said Javier 
Salido, a senior program manag- 
er at Microsoft. 

One of the key takeaways was 
that Microsoft has a new website 
about data governance that can 
serve as a reference for develop- 
ers. The site offers detailed 
information about how to cope 
with statutory and regulatory 
environments, data governance, 
the information life cycle, and 
how organizations can develop 
their own action plans. 

Salido discussed each of 
those topics during his presen- 
tation, and he stressed that pri- 
vacy has to be embedded into 
the application development 
life cycle from the very begin- 
ning. Organizations should only 
collect data necessary for doing 
business and set requirements 
around how data is collected, 
processed and shared, as well as 
who has access to it at each 
stage, he said. 



Data governance is necessary 
for properly handling data across 
the enterprise, and it encom- 
passes people, processes and IT, 
Salido said. He also said that gov- 
ernance maximizes the benefit 
received from data assets, helps 
organizations remain compliant 
with regulation, and is important 
for successful risk management. 

A technology framework is 
necessary for data governance 
that includes auditing and 
reporting, identity and access 
control, information protection 
(for both structured and 
unstructured data), and a 
secure IT infrastructure that is 
protected against malware and 
unauthorized access. 

Organizations can begin to 
safeguard privacy by writing an 
action plan, Salido said. The 
plan should include technical 
controls, examine the organiza- 
tion impact of changes, cata- 
logue sensitive information, and 
be guided by the principle that 
technology is only part of the 



solution, he explained. 

Last year, a majority of data 
breaches involved data that was 
not known to reside on the 
affected system at the time that 
the incident happened, he said. 
That kind of negligence is not 
permissible under an increasing- 
ly stringent regulatory landscape. 

The U.S has a patchwork of 
laws specific to industries or 
data-breach protection, he said. 
Other laws govern Personally 
Identifiable Information (PII) 
such as Social Security numbers 
or drivers license numbers. 

Companies can cope with the 
complexity of those laws by fol- 
lowing industry standards, 
including IEC CD 29100, which 
provides best practices to devel- 
op applications that safeguard 
privacy, and NIST SP 800-122, 
draft U.S. government guide- 
lines for managing PII and plan- 
ning for breach incidents. 

While standards tell you 
what to do, they don't tell you 
how to do it, said Salido. 
Microsoft publishes privacy 
guidelines and an IT Compli- 
ance Management Guide. I 
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Mykonos touts secure AJAX 



New framework has built-in client and server filtering components 



BY JEFF FEINMAN 

A new AJAX company is imple- 
menting built-in security mea- 
sures on the server, the trans- 
port layer and on the client for 



every application created. 

Executives of startup 
Mykonos said every that com- 
ponent within the company's 
AJAX framework is built to fil- 



ter user data in order to make 
AJAX development more 
secure. This is done, they said, 
by validating cross-site requests 
using encrypted tokens, and by 



using proprietary CAPTCHA 
codes and authentication 
screening techniques to pre- 
vent automated log-ins. 

Mykonos is a framework for 
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building enterprise-class Web 
applications, and it includes a 
feature called Visual Builder 
that allows developers to create 
screens and workflows. There is 
a set of components for data 
transfer that are already 
encrypted to prevent against 
SQL injections and other 
attacks. 

The name Mykonos was 
adopted when company execu- 
tives were sitting in their 
Rochester, N.Y. office on a cold, 
wintry day. 

Protected only by office 
walls from the blistering, snowy 
weather, one employee looked 
at a framed picture of the 
Greek island Mykonos, a land- 
mass known for its sandy 
beaches and exquisite nightlife. 
The employee proclaimed he'd 
much rather be there instead of 
Rochester. Hence, the idea 
came about for the company 
name. 

The company is a subsidiary 
of BlueTie, a software-as-a-ser- 
vice e-mail and collaboration 
company. Mykonos was split off 
from BlueTie and launched as a 
separate unit in late April. It 
has offices in Rochester and 
Palo Alto, Calif. It currently has 
15 employees. 

CEO David Koretz called 
Mykonos a "framework coupled 
with a security service." 

He continued: "You've got a 
layer of secure components, 
you've got code around your 
RPC layer, and then you've got 
code around your logging and 
auditing engine and other 
things that exist on the client. 
Mykonos can actually use all 
this security to upgrade the 
code itself." 

For instance, if there is a 
security issue around Firefox, 
Mykonos can update its compo- 
nents in real time to defend 
against that, Koretz said. 

Mykonos hired developers 
who didn't have expertise in 
browser compatibility and Web 
application security, Koretz 
said. This helped create a 
framework that allows any 
developer with object-oriented 
development experience to cre- 
ate Web apps. 

"We dramatically reduce the 
need for people to become 
JavaScript experts," Koretz 
claimed. "Not all developers 
will become experts in 
JavaScript, and not all of them 
will become experts in browser 
compatibility, and certainly the 
vast majority of them won't be 
experts in security. So we take 
those big issues off the table." I 
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JNBridge spans .NET-Java message gap 

Software helps developers without knowledge of both platforms 



BY ALEX HANDY 

Despite having a mostly symbi- 
otic relationship in most enter- 
prises, there are still areas in 
which Java and .NET don't 
play nice. One such area is 
around the Java Message Ser- 
vice, which acts as a message 
queue for large distributed 
Java applications. JNBridge 
targets this disconnect with its 
self-titled product for integrat- 
ing such queues into .NET 
applications. Version 1.2 was 
set for release on June 1 and 
brings with it the software's 
first support for going back and 
forth across such message 
queues. 

Wayne Citrin, cofounder 
and CTO of JNBridge, said 
that the entire array of JMS 
services is supported on .NET 
through his company's prod- 



uct. "We provide access to the 
entire JMS capability: all the 
JMS messages, local transac- 
tions, JMS security and 
authentication, as well as 
access to JMS headers," said 
Citrin. 

"[Our customers] use our 
product because the alternative 
to using a product like ours is 
probably WS-*, and there are 
problems with throughput." 

For those developers using 
Microsoft BizTalk Server for 
business process management, 
Citrin said that the JNBridge 
1.2 update finally gives them 
the ability to move back and 
forth between JMS and BizTalk 
programatically 

"We've been looking at the 
needs of our financial services 
companies," he said. "There's a 
lot of need for what we do, and 



it's gotten more urgent with all 
the mergers that have been 
going on. What the financial 
services customers have been 
asking for is the ability to inte- 
grate the transactions that exist 
on both sides. Up until now, 
we haven't had the ability to 
integrate the cross-platform 
transactions, and nobody has 
outside WS_Atomic_Tansac- 
tions, which is ambiguous." 

That back and forth should 
make troubleshooting a lot eas- 
ier for developers tracking 
down issues across multiple sys- 
tems, said Citrin. 

"When you're reading in a 
block of messages from JMS in 
the context of a .NET transac- 
tion, if that fails, not only do 
you need to roll back the 
actions in the consuming .NET 
code, you also need — in the 



same transaction — to put those 
messages back on the JMS 
queue, so when things are re- 
fed, you can read those mes- 
sages again and no data will be 
lost," said Citrin. That capabili- 
ty has been added in 1.2, he 
added. 

Still, the biggest reason to 
use JNBridge, said Citrin, is to 
save your .NET developers 
from having to learn the 
vagaries of JMS. "The users, if 
they're skilled in the .NET API, 
don't have to know anything 
about JMS programming. You 
simply fill out a property sheet 
with some info like initial con- 
text, the names of the queues 
you want to access, and the 
locations of the JAR files," he 
said. JNBridge handles the 
interchange code automatically, 
he added. I 



SDL templates going into Visual Studio 



< continued from page 1 

security initiatives, and the 
SANS Institute. 

The template follows version 
4.1 of the SDL document, pro- 
viding auditable security 
requirements and project status 
information, as well as demon- 
strating a security return on 
investment, Ladd said. It is 
designed to provide guidance for 
customizing the SDL process for 
individual projects, and it 
includes an XML schema to 
import data from testing tools. 

The schema is primarily 
designed for automating the 
integration of Microsoft's threat- 
modeling tool, but it also works 
with third-party tools that can 
format content for Team Foun- 
dation Server, said Ladd. 

SDL 4.1 documentation was 
also published in May on 
MSDN. It includes updates to 
prior requirements and docu- 
mentation, new guidance for 
online services and line-of-busi- 
ness application development, 
and closer alignment to tradi- 
tional software development 
life-cycle phases. 

"We made [the SDL] more 
complicated than it actually 
was," Ladd acknowledged. 
"Now, we've reduced the SDL 
to discreet steps. Organizations 
can make security gains without 
being security experts." 
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Microsoft created the SDL template to make its secure development processes easier for developers to implement. 



A final security review 
demonstrates the progress that 
is being made toward complet- 
ing all SDL tasks and how a 
team is doing against require- 
ments, Ladd said. 

"People cannot execute any- 
thing flawlessly no matter how 
well-defined or well-explained," 
said Rex Black, president of Rex 
Black Consulting Services. As 
an example, he noted that many 
of his clients find reasons not to 
execute automated unit testing 



even though it is a clear rule for 
agile development. 

"In the same way, people 
will carve out exceptions to the 
SDL for themselves, in some 
cases for legitimate reasons, in 
some cases not. This increases 
the percentage of security bugs 
that slip past," he said. 

A dashboard is provided 
with the SDL template for 
development managers to track 
the progress that is being made 
toward meeting SDL require- 



ments, Ladd said. 

The template allows project 
owners to give requirement 
updates, and it pumps data into 
Team Foundation Server, he 
added. An SDL document 
library is available to process 
participants through a Share- 
Point site. 

"Even if a strategy is executed 
flawlessly, no strategy for dealing 
with risk is 100% effective. So, 
bugs will remain," Black con- 
cluded. I 



Apache Sling 
handles Java 
Web content 

< continued from page 1 

ageable. Therefore we choose 
OSGi as the underlying plat- 
form." 

Day Software, the company 
behind much of the work on 
Apache Sling, started on this 
path toward a development 
environment focused on JSR- 
170 (Java Content Reposito- 
ries), when its current CTO, 
David Nuescheler, became 
specification lead on JSR-170 in 
2002. The spec was finalized in 
2005, and just under two years 
later, Nuescheler's coworkers 
began building the Apache 
Sling framework to manage 
connections between Java 
applications and their JSR-170- 
compliant JCRs. 

The idea is to stick all that 
Web content in a simpler 
repository, rather than spread- 
ing it around the hard drive of 
each Web server. Thus, con- 
tent developers can slot 
images, text and other items 
into the content repository, 
rather than trying to keep track 
of individual assets as they 
move through the many seg- 
ments of a company. Because 
the JCR manages content in a 
manner similar to an SCM sys- 
tem, developers using Sling 
can quickly tie this information 
into portlets or beans. 

At Switzerland-based Day 
Software, Felix Meschberger 
(who can be seen as the father 
of Sling), Bertrand Delacretaz 
and Ziegeler worked to build a 
new API for dealing with con- 
tent repositories. Said Ziegeler: 
"While the original idea was to 
have a framework based on 
JCR, it took us some time to 
recognize that we shouldn't do 
that. [Rather,] base the whole 
framework on a more generic 
abstraction (which we call the 
resource API). 

"Getting this API right, and 
providing enough functionali- 
ty — but not too much — was the 
most tricky part. We spent 
nearly a year on this. But today 
we are very proud of this API as 
it makes Sling even more pow- 
erful and elegant." 

This API layer allows devel- 
opers to use scripting languages 
or straight Java to dictate how 
Web content is handled on its 
way to the client- side. I 
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/That's how "2008: An Economic Odyssey" played. The year 
^was filled with images of layoffs, cutbacks, going-out-of-busi- 
ness signs and more. Pundits said the technology sector held up 
better than most, showing only that "weak" is better than "down" 
in financial terms. Meanwhile, companies lived quarter to quarter, 
hoping they didn't simply fade to black. 

To be sure, there were bright spots with the emergence of cloud 
computing and composite applications. Amazon was the star of 
that picture, but other platform providers sought billing. For devel- 
opment managers, the line they kept hearing was, "Do more with 
less." Agile development practices played a larger role. And with 
the move toward services came an increase in the use of open- 
source software, as companies looked to cut costs and increase 
time-to-market. This created a market for governance and certifica- 
tion software. 

It was the year that most of us found Facebook and learned to 
tweet on Twitter. These social media sites proved that collabora- 
tion is easier than ever. For distributed teams, "development as a 
service" followed this trend as hosted platforms accessed via a 
browser emerged and grew. 

So here are the companies that led the way to this new software 
world through their ideas, inventions and new implementations. 
The 7th SD Times 100 are ready for their close-ups! I 




No two developers-or development tool providers-will ever agree about 
what's included within application life-cycle management. How much does 
iM ALM focus on an individual developer's productivity? The team? The orga- 
\ nization? The lack of a clear definition hasn't stopped some of the industry's 
most innovative companies from offering tool suites that encompass the entire 
iffk.^ application life cycle. In some cases, these organizations have demon- 
strated leadership by creating innovative ALM solutions from the ground 
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m up. In other cases, they have led by integrating once-distinct products. 



Atlassian * CollabNet * Electric Cloud * IBM * Kovair 
MKS * Seapine * Serena * TechExcel * UrbanCode 





Last year may have been The Year of the Cloud. It was hard to attend any hj 
software-development forum (or any information technology event) without i 
seeing the phrase "cloud computing" in 20-foot letters. The economic reces- 
sion, combined with emerging hardware and software platforms, com- 
bined to create a perfect storm. Behind that storm stood three compa- 
nies, whose names became ubiquitous. While their approaches to cloud 
computing were different, these companies have gained early momentum. Today, the 
industry now looks to them for leadership during nascent standardization efforts. 





The saying goes that the most innovation happens at startups. That may be true, but 
the long tail is generally wagged by the biggest companies and organizations in 
our industry. The companies recognized as Influences in the SD Times 100— 
T^ whether they're Apple with the Mac and iPhone, or Microsoft with Windows and 
* Office-have had a profound impact on many, many, many areas of information 
technology and software development. Their influence is felt everywhere, from 
the desktop to the Internet, from the laboratory to the business meeting. 



Amazon * Google * Salesforce 
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Apple * Eclipse * Free Software Foundation * IBM 
Intel * Java Community Process * Linux Foundation 
Microsoft * Oracle * OSGi Alliance * VMware 




Smart software developers like to write software. Smarter software devel- fyj/ 
opments-and their managers-know that it's often better to reuse code than ■.* 
write it from scratch. Code reuse has been the goal of developers from time JjL 
immemorial, whether it's grabbing a box of math routines punched onto mm 
Hollerith cards or loading a library of GUI widgets. This year, the SD 1^1 
Times 100 recognizes the innovators and leaders in reusable compo- ™^H1 
nents and libraries, focusing on those companies that have stayed on top of the lat- 
est platforms and protocols. 



Amyuni * Aspose * ComponentOne 

ComponentSource * DevExpress * Dundas 

Infragistics * Intersoft Solutions * /n Software 

Nevron * Software FX * Syncfusion * Telerik 
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It has become hard to tell where the application server ends and the data- 
base server begins. Over the past several years, database servers, which 
pf we used to call relational database management systems, have grown in 
! • complexity and sophistication while offering new flexibility for scalability 
1 and performance. Similarly, database tools have evolved as well. Yester- 
J^ day's DBA wouldn't recognize today's RDBMS. This year, we recognize 
" those organizations that have led the advancement of database tech- 
nology through their leadership in servers, developer and DBA tools, 
and data access technologies. 




CA * Embarcadero * Enterprise DB * IBM 
Ingres * Microsoft * Oracle * Red Gate * Sybase 
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You got your peanut butter in my chocolate... and we ended up with a new V 
type of candy. Your developers wanted to add a geographic display of your * 
company's retail locations to your website, and so they incorporated 
Google Maps. Development teams have mashed applications together 
for years, of course, through ad hoc integration of disparate applica- 
tions and data sources. Service-oriented architectures accelerated the 
trend, making mashups easier to make-and less brittle-than ever before. We recog- 
nize three leaders that have taken the concept farther than any others. 




JackBe * Serena * Tibco 
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The bigger the project, the more important modeling becomes to achiev- jd&g\ 
ing success. We've learned, of course, that modeling can take several |£ 



forms; while many extol the virtue of the Unified Modeling Language, the 
most important element in a successful model-driven approach to software 
development is that developers actually use the models, no matter 
whether the models are standards-based or not. We recognize four 
organizations that have demonstrated leadership by advancing the 
state of modeling in software development, whether through the use 
of specifications, integration or tool usability. 




IBM * Microsoft 
Object Management Group * Sparx 
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Defects happen. No matter how hard your coders try, errors will creep into 
the software. Not all the faults are programmatic; some defects are caused 
by architectural issues, the failure of dependencies, or even a misinterpreta- 
tion of requirements. (And some defects are reported because require- 
ments changed.) Many companies and projects stand ready to help your 
stakeholders measure, identify and remediate defects in your pro- 
grams. From makers of individual tools to entire QA sites, the SD Times 
100 recognizes leaders and innovators in the software quality-assurance field 
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Dynatrace * Gomez * Hex-Rays 
Hewlett-Packard • IBM * iTKO • McCabe • Parasoft 
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Hybrids between client/server and Web applications, rich Internet applications com- 
bine the power of remote hosts with the performance and resources of locally run- 
ning code. While there are many approaches to RIAs, the strongest suc- 
cess has come to those industry leaders that have taken a broad, 
platform-agnostic approach to the problem. This year, the SD Times 
"J^ 100 recognizes three players whose RIA platforms have become the de 
1 facto standard. While other RIA platforms fill important needs, they lack 
the broad appeal of solutions from these companies. 
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It may not be the sexiest area of software development, but SCM is the bread and 
butter of application life-cycle management. Without a platform to manage 
source code, control check-in and check-out, store artifacts, and exercise ver- 
sion control, development projects can't scale and can't succeed. Today's 
leading SCM platform makers, recognized in this year's SD Times 100, do even 
more: They integrate with defect management, requirements management and 
build systems; provide reports to team leaders and business executives; 
enable team communication; and foster a culture of quality. 



Git * Perforce * Seapine 
Sonatype * Subversion 
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I Nothing ruins your day more than finding that hackers stole your company's 
08f^ most sensitive data. Unless, perhaps, it's that someone did something 
SM worse. Security vulnerabilities can be introduced anywhere in the applica- 
R tion life cycle, perhaps from simple coding errors, or because enemies exploit- 
ed a flaw you never knew existed. There are many techniques for finding secu- 
^^^ rity vulnerabilities, and the innovative companies in this category have 
demonstrated that their products and services make a real difference. 




Coverity * Fortify * Klocwork * Microsoft 
Progress * SafeNet * Selenium * Veracode 
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''Break free of your silos," cry advocates for service-oriented architectures. Extend 
the usefulness of your applications by tying them together using standards- 
based middleware, such as those based on the various Web service specifica- 
tions. By using smart middleware, and by adding Web services to applications, ^ 
enterprise software can become smarter as well, and the cost to create new func- ' 
tionality can plummet. These companies have demonstrated leadership and 
innovation in SOA enablement and in creating enterprise middleware. 

Active Endpoints * Hewlett-Packard * InterSystems 
iWay * Programming Research * Rally * Tibco * WS02 
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What determines developer productivity? While sophisticated platforms are 
essential for teams, individual programmers are only as effective as the tools on ; \ 
their desktops. Some programmers use discrete tools, bringing together code a 
editors, compilers, debuggers and more. Others work in an integrated devel- 
opment environment, preferably one tied into other enterprise development 
platforms, like SCM systems. The SD Times 100 recognizes these companies 
and organizations as leaders in tools and IDEs for enterprise developers. 




ActiveState * Altova * Black Duck * Eclipse 
Embarcadero * Instantiations * Jruby * Microsoft * Sun 
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Building websites and Web pages is different from creating traditional client and 
server applications. Not only is the Web paradigm unique, but Web developers 
also use special languages and protocols. They have specific issues regarding JL 
functional and load Ug. What's mate, requirement" may be vague agili -** 



1 



ty paramount, and the rollout process abbreviated. These companies and orga 
nizations showed a profound understanding of what enterprise Web developers ■" 
need, and they help developers build Web applications faster than ever before 



Adobe * Eclipse * Google 
Microsoft * Ruby on Rails * Sun 
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Taking the processes 
enterprise-wide 
requires greater 
discipline, and 
some heavy-duty 
management tools 



BY DAVID RUBINSTEIN 



The notion of agile development by 
now is well known for most every 
responsible CEO and CIO. With 
the economy stuck in low gear, organi- 
zations need to find ways to shorten 
development cycles and improve quali- 
ty all with the resources they already 
have on hand. 

The Agile Manifesto, which spells out 
the ideas and practices for its implemen- 
tation, was written in 2001, and in the 
eight ensuing years, many organizations 
have taken the first steps toward agile 
development. By now, many have had 
successful projects done by designated 
agile teams and have realized the cost 
savings and time-to-market benefits that 
agile espouses. 

Now, these organizations want to reap 
bigger benefits by bringing agile out of 
its silos and into a wide deployment, 
across geographical locations, time zones 
and language barriers. Yet among the 
Manifestos 12 core principles are that 
"the most efficient and effective method 
of conveying information to and within a 
development team is face-to-face con- 
versation," and "business people and 
developers must work together daily 
throughout the project." And there's the 
one about "individuals and interactions 
over processes and tools." 

Those principles would almost seem to 
inhibit the adoption of agile processes in a 
large, distributed development organiza- 
tion. So how do organizations scale their 
agile practices to get a bigger payback? 

NOT TO SCALE? 

Robert Holler, CEO of agile project man- 
agement software maker VersionOne, 
took a step back to answer that question. 
"There are challenges with scale. The 
problem s not unique to agile or to soft- 
ware development," he said. "Scaling is 




just tough. Sometimes agile gets a black 
eye for not scaling, but it's more like, 
'Development doesn't scale.'" 

And Paul Hodgetts, lead consultant at 
Agile Logic, said that planning before 
embarking down the agile path is critical. 

"There's no way to get a big organiza- 
tion behind something like this without 
first thinking it through," he said. " 'Why 
are we doing this? How will we get 
everyone on board?' You must show 
them a way to get from point A to point 
B that won't make their lives miserable 
for the next 12-18 months." 

Too often, he said, organizations fail 
and blame it on the methodology. "They 
say, 'We tried to implement agile, but we 
didn't plan or learn about it, so it didn't 



work, so agile sucks.' " 

Holler agreed that the foundation for 
agile must be built before adoption can 
be successful. Among the factors organi- 
zations need to assess are whether the 
educational base to scale already exists. If 
the answer is no, the organization must 
decide if it is willing to bring in the exper- 
tise. "If not, it's an impediment," he said. 

"People say, 'We want to scale but we 
don't want to invest' in education. That 
won't work. [Education] is a fundamen- 
tal tenet of success." 

Another fundamental issue for enter- 
prise-wide agile development is buy-in. If 
you can't get everyone in the organization 
to agree with the approach, success will 
be impossible to achieve, said Hodgetts. 



"Agile is hard and it takes a lot of 
commitment," he said. "Every enter- 
prise implementation I've seen is a 
roller-coaster ride. They implement it in 
one team, see some productivity 
improvements, better quality software, 
and then that the people are happy. But 
when they try to bring it wider, they stir 
things up — maybe they move people off 
the successful teams to coach newer 
people — and they might actually lose 
productivity for a time. 

"As an enterprise, you've got to be 
prepared to live through a number of 
cycles like that." 

In practical terms, though, scaling 

across a large, distributed organization 

continued on page 29 ► 
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The war between dogma and degree 

Hdw much agile process must he adopted for organizations to call it a success? 



BY DAVID RUBINSTEIN 

So, just how agile is your agile process? 

While those who preach the dogma 
of the Agile Manifesto have loosened 
their belief that agile is an all-or-nothing 
affair, debate continues over what con- 
stitutes an agile development shop. 

On one side of the argument are those 
who believe that adopting any of the steps 
is a move toward agility; that the impor- 
tant thing is not adherence to the steps 
but instead an improvement in the orga- 
nization's software development. Others 
acknowledge that any improvement is 
beneficial, but the technique employed 
can't be called agile if the practices of XP, 
or Scrum, or the other agile methodolo- 
gies are not followed to the letter. 

"Any really meaty trend has great dog- 
matism to get started. Otherwise, who's 
going to follow you?" said VersionOne 
CEO Robert Holler. "You throw the 
gauntlet down and get followers. There's 
nothing like great controversy to make 
things happen. It had to start that way." 

That said, Holler noted that extrem- 
ism about agile might not be every orga- 
nization's reality. "People are realistic 
enough to know they can localize it to 
meet their internal business require- 
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Process maturity comes from within, not 
from a vendor cookbook, says Martens. 

ments. They might water things down, 
but are they improving? It's come to a 
reasonable state now. When applying 
agile in mainstream software organiza- 
tions, you can't change overnight. But 
are things improving?" 

Consultant Paul Hodgetts of Agile 
Logic said he's seeing a lot of agile devel- 
opment happening in enterprise shops 
at varying degrees of implementation. 
"Agile seems to be on the radar for most 



CEOs and CIOs, like offshoring was a 
couple of years ago. They're at least 
looking into it to stay current. 

"The ones that are implementing 
deeper and broader and getting real big 
payoffs are limited," he continued. "I'd 
say one out of 10 big organizations are 
really taking it deep enough across the 
organization" to see the big payoff, he 
said. "One-third to one-half stall out 
pretty quickly. They hit plateaus and 
they stop. There are some organization- 
al changes they'd have to make that they 
either can't or are unwilling to get past." 

There are ways to measure an organi- 
zation's level of agile implementation. 
IBM describes it with its own Agile 
Process Maturity Model, which defines 
three levels of process maturity. Rally 
describes something it informally calls 
the "Flow, Pull, Innovate" method. 

In a lengthy blog posting, Scott 
Ambler, IBM's practice leader for agile 
development, defines level 1 of the 
APMM as having adopted Scrum, XP, 
agile modeling or agile data modeling, 
and testing or refactoring. Level 2 calls 
for more discipline in the development 
life cycle, including the use of hybrid 
processes, such as Scrum and XP. Adop- 



tion of the Rational Unified Process, the 
Open Unified Process, Harmony for 
embedded systems, or Dynamic System 
Development Method, which was based 
on Rapid Application Development, 
helps organizations get to this level. 

The top level calls for agility at scale, 
taking into consideration such things as 
physical distribution of the team, regula- 
tory compliance, system complexity and 
enterprise disciplines. The APMM, 
Ambler writes, is "orthogonal to the 
[SEI's] Capability Maturity Model Inte- 
gration [and] strives to define a frame- 
work which can be used to put the myr- 
iad agile processes into context." 

But Rally Software founder Ryan 
Martens believes existing measurements 
of development process maturity are 
just fine. "The CMM model applies for 
agile as well as waterfall projects. We 
don't need another model. To me, that's 
a vendor cookbook." 

Martens said that to achieve process 
maturity, an organization needs to look 
within and not have a vendor tell you 
where you are at. "Our model is to look 
for teams to get a flow, a repeatable capa- 
bility of delivering what they're commit- 
ted to," he explained. "You get the drum- 
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beat. You understand how to deliver in a 
two-week time box." 

This is also where developers build 
confidence at the senior management 
level to dive into more agile develop- 
ment. Then you have to move the team 
from the flow to pulling work as required, 
such as pulling out a build to test for 
security or performance, to eliminate the 
backlog of requests. "You've figured out 
the organizational problems and road- 
blocks," Martens said. 

Finally, to scale to these practices, 
multiple teams or disparate organizations, 
a top-down push is needed. "They [top 
executives] have to provide enough slack 
time to innovate," Martens said. "You 
have to be able to take advantage of the 
things that are falling onto your plate." 

All of which makes open-source 
ALM company Atlassian very nervous. 
"We feel the term 'agile' is a loaded 
term," said director of product market- 
ing Daniel Freeman. "We don't want to 
be typecast as a process Nazi." 

Atlassian recently purchased the 
GreenHopper plug-in to convert its 
JIRA tool from bug-tracking to an agile 
management tool for Scrum. "We don't 
want to position Atlassian as an agile 
company," said Freeman. "To us, agile 
means what works right and best for 
your team. Each organization adopts 
agile methodologies differently. Let 
them adopt them in whatever fashion 
they like." I 



Scaling agile development 



< continued from page 27 

poses several challenges. The tried-and- 
true methods of developing in pairs in 
the same room, and using a whiteboard 
at daily standup meetings, or even hav- 
ing those meetings, don't carry over to 
teams that are geographically dispersed 
and working on an around-the-world, 
24-hour schedule. 

ENTER THE TOOLS 

The original 17 signers of the Agile 
Manifesto were mostly consultants and 
developers; as a result, the notion of 
small, co-located teams doing pair pro- 
gramming and constantly engaging the 
customer were top of mind. To go with 
this, a number of excellent point solu- 
tions were created for continuous inte- 
gration, for functional and acceptance 
testing, and for managing change. 

But these solutions optimize parts 
that can be leveraged by small teams, 
leaving organizations to do a lot of tool- 
smithing to integrate the pieces into an 
enterprise-scale solution, according to 
Scott Ambler, the practice leader for 
agile development at IBM. 

"The overarching platform has to 
provide value for developers, or they 
won't use it," he said. "Continuous inte- 
gration is great. Testing is great. But 




VSTS 2010 MORE AGILE 



Visual Studio Team System 2010, Microsoft's collaborative development environ- 
ment, will introduce features that both align agile methodologies with project man- 
agement and help developers from a "fingers on the keyboard" perspective. 

VSTS 2008 introduced agile templates within Team projects; 2010 uses more of 
the terminology agile developers are familiar with, including user stories, sprints 
and the like, according to Doug Seven, senior product manager for VSTS. The tem- 
plates had already used terms familiar to developers using the Microsoft Solutions 
Framework for Agile Development. Also with 2010, the templates can now be saved 
by iteration to the Team Foundation Server (TFS), from which subsets of stories can 
be pulled down and broken into tasks using a parent/child hierarchy. 

Further, 2010 adds SharePoint Server support, so that when a Team project is 
created, a SharePoint portal for that project is automatically created or an existing 
portal is pointed to, Seven explained. The SharePoint dashboard, linked to the TFS 
installation, pulls in data to create a landing point for all information associated 
with the project. The reporting within VSTS 2010 now uses more descriptive text, 
with burn-down and velocity reports presented in formats agile developers are used 
to. For project management, the planning worksheets, product backlog lists and 
more all are based in Excel for ease and familiarity, he said. 

"The idea behind agile is to make it attractive by delivering value iteratively," 
Seven said. "It's less about checking things off a list. There's a learning curve and 
challenges with any new process or tool sets. We want to give tooling that is intu- 
itive and supports developers. We are paying attention to the agile community." 

— Da vid Rubins tein 



they're having to do a lot of toolsmithing 
to make it work." 

On a management level, automated 
metrics offer tremendous value, he said. 
"Manual metrics is a lot of wasted effort. 
You need a coherent metrics program in 



place or you'll have problems adopting 
agile in a meaningful way." 

IBM's Rational Team Concert pro- 
vides an integrated tool set for the agile 
life cycle, Ambler said. Rational Require- 
continued on page 30 ► 
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Discipline and management tools 



< continued from page 29 

ments Composer offers lightweight agile 
modeling; Quality Manager tackles 
usability and security issues while man- 
aging parallel testing efforts; AppScan — 
though not yet based on IBM's Jazz tech- 
nology — offers security testing for 
Web-based applications; and Software 
Analyzer is a static code analyzer that 
keeps agilists more focused on quality 

Ambler acknowledged there are 
"some great open-source tools" out 
there, but at the end of the day, "we see 
team after team spending so much time 
on integration. They should be develop- 
ing applications for their own organiza- 
tion. Doing all this toolsmithing is not a 
great use of their time." 

Tools should not lock a user into a 
particular discipline, cautioned Ryan 
Martens, founder of agile project man- 
agement software provider Rally Soft- 
ware. "It's more about picking a partner 
that keeps you on the path" toward a 
mature agile process, he said. "Other- 
wise, you end up with a heavy process 
that's not well lined up with agility." 

Rally's software, simply called Rally, 
focuses on project planning and manage- 
ment, Martens said. The software inte- 
grates with development tools for Eclipse, 
.NET, scripting and embedded projects, 



THE PROS 7 DO AGILE BETTE 



Agile comes easier, and results in greater success, in organi- 
zations where building software is their business, such as ISVs 
and Web companies like Amazon, eBay and Google. 

That is the experience seen by Mike Jones, OutSystems' 
vice president of marketing. 

"Corporate IT is a different beast. The natural inclination is 
for people to say they don't have professional developers. We 
don't see that," he said. 

Three key differences between corporate development and 
"professional" development are budgets, the nature of the 
development team, and where the direction, features and 
focus for the application are coming from. 

"An ISV is in business to build apps," Jones said. "At BMC 
[in 2000 to 2003, when Jones was there], we had a large bud- 
get. We didn't have to lobby for more. They don't worry about 
having to champion for dollars to add features. In corporate IT, 
you have to have a business case. You need a scope and a def- 




inition so you can get funding to build the app. It starts to 
make agile not so agile." 

As for development teams, Jones said that at ISVs, devel- 
opment teams are stable and developers work together on an 
ongoing basis. In corporate IT, "there seems like there is 
always a lack of resources. From project to project, sometimes 
they outsource, sometimes they bring in a consultant. That 
puts pressure in-house to support and maintain those apps. 
You need heavy documentation." 

Finally, Jones said, the direction, focus and features for 
applications created at ISVs and the Web companies usually 
comes from a project manager who's exploring reguirements 
on the delivery train, as well as working with customers and 
end users. Corporate IT "doesn't have that," Jones said. 

"In corporate IT, the project manager is a business guy. It's 
something they do on the side. They don't embrace or deliver 
the agile approach." —David Rubinstein 



he pointed out, and also lets organizations 
assess their agile prowess and bring in ele- 
ments of coaching and training. "There 
are a lot of choices available at the devel- 
opment tool level. We don't provide tools 
for individuals. Those pieces get integrat- 
ed with our products," he said. 

Borland Software, which was recently 
acquired by Micro Focus, transformed 
its in-house development to agile at the 
end of 2006. The company has develop- 



ment centers in Austria, Australia, Singa- 
pore and Santa Ana, Calif. To achieve its 
goal, the company created Borland 
TeamFocus, an electronic team board 
that enables project management. 

"We built out team rooms and use 
projectors for virtual corkboards," said 
Chuck Maples, senior vice president of 
research and development at Borland. 
"You can click on the corkboard and cre- 
ate tasks, and then drill into those tasks. It 



was all designed with an enterprise agile 
model in mind. It's been very successful 
for us. We've improved quality, shortened 
our release cycles and increased the pre- 
dictability to the business." 

VersionOne is also focused on project 
planning and management with its VI 
software, and it now has Java and .NET 
SDKs to allow integrations with organiza- 
tions using those technologies. In late 
May, the company announced VI will 
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needed for agile to scale up 



include IdeaSpace, modeled 
after Salesforce.com s IdeaEx- 
change, for high-volume tactical 
planning, prioritization and col- 
laboration, VersionOne's Holler 
explained. "There's nothing like 
an economic downturn to deliver 
some new functionality," he 
quipped. 

IdeaSpace, written by Ver- 
sionOne to tightly tie in to its 
agile platform, is a place for the 
business side and developers to 
write stories and get feedback 
from customers. It supports 
multiple forums, with security, 
and lets managers see who's 
generating the most requests 
and who's responding the most, 
as well as other information for 
use in the planning cycle, 
Holler said. 

OutSystems offers agile plat- 
forms for an on-premises devel- 
opment, delivery and operations 
management environment, and 
Agile Network as software-as-a- 
service for managing agile pro- 
jects, including training and 
forums. Among the important 
features of the software is a siz- 
ing and scoping tool that lever- 
ages user stories to define the 
scope of a project, so an accu- 
rate budget can be generated, 
according to Mike Jones, vice 
president of marketing for Out- 
Systems, which has more than 
half of its customers making 
changes to and building custom 
packages for SAP environments. 

One of the keys to the Out- 
Systems platform is the "true 
change engine" built into the 
platform's model-based reposito- 
ry environment, which enables 
users to understand the impact 
of a change to the code and pro- 
vides self-healing impact analy- 
sis; it either fixes a problem or 
reports on it. Further, Agile Net- 
work provides a place for end 
users to insert comments along- 
side a running application, and 
developers can launch the code 
underneath that submission 
screen to make the change, 
Jones briefly explained. 

"End-user acceptance flies 
through because it's been so 
vetted by that point," he added. 

To scale for the enterprise, 
Jones said OutSystems found it 
had to break some Scrum-type 
roles to leverage remote 
resources. "We split the tradi- 
tional role of Scrum Master into 
an engagement manager, who's 
always with the customer, 
understanding the feedback, 



setting expectations and leading 
the demo at the end of every 
sprint; and a delivery manager, 
who is where the development 
team is and who owns the archi- 
tecture, the application, and 



who's responsible to set the 
scope and deadlines," he said. 

Even with tooling, Agile Log- 
ic's Hodgetts said the agile advo- 
cates within large organizations 
get that it requires a change in 



their approach to development. 
"You can't just purchase agile 
and install it and be done with 
it," he said. "You can't just buy 
VersionOne and say, Tm agile,' 
or hire Paul [Hodgetts] for three 



training sessions and say, 'Now 
I'm agile.' " 

There are some common 
themes that most agree are the 
first steps down the road to agile 
development: running in shorter 
cycles, higher visibility, and 
worker collaboration. "Getting 
those cores in place are critical 
to success," Hodgetts said. I 
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FROM THE EDITORS 

Clouds and mashups 

If there's an underlying theme behind this year's SD Times 100, it 
involves the Internet. This reflects a sea change. 

In the not-too-distant past, enterprise software development projects 
were contained within the enterprise. Server and mainframe applications 
ran within their data-center silos. End-user applications ran on desktops 
and notebooks. Client/server applications leveraged the corporate LAN; 
the closest they might come to touching the Internet would be remote 
access via a virtual private network. 

As time went on, more and more enterprise developers learned about 
the Web. The initial brochureware websites became full-fledged client 
applications, using sophisticated front ends to provide secure access to 
some business data, such as a customer's account information or a real- 
time inventory lookup. For the most part, however, enterprise applica- 
tions lived in their silos, with the only Internet touchpoint being brows- 
er-based access to public-facing customer applications. 

Now, look at the categories in the 2009 SD Times 100. One new cat- 
egory is Cloud Computing. Another is Mashups. While those concepts 
aren't every organization's cup of tea, their importance in today's business 
environment can't be overstated. 

With cloud computing, companies are pushing their own custom 
applications out to remote data centers running at companies like Ama- 
zon.com, Google or Salesforce.com. Unlike traditional hosted applica- 
tions, these truly are custom applications, written by the enterprise or its 
consultants for the exclusive use of the enterprise. 

As cloud development matures (it's odd to write "matures" for a trend 
that's truly in its infancy), organizations are able to utilize many different 
cloud platforms, underlying data and storage services, programming lan- 
guages, and APIs, all with varying service levels of guaranteed uptime, 
bandwidth and performance. It's enterprise computing, served up with a 
large helping of Internet infrastructure. 

Mashups present an entirely different opportunity, granting develop- 
ers and power users the ability to leverage code reuse on a massive scale. 
Consider how Vi Labs is using Google Maps to help organizations track 
down software pirates. (Read the story on page 6.) Is it mission-critical? 
Not necessarily. Could the company have implemented mapping without 
mashups? Certainly. Was this an easy, inexpensive way to add functional- 
ity to an application? Definitely. 

Best and brightest 

The SD Times 100 recognizes the best and brightest companies and 
organizations in the software development industry. This is not a 
product award, and we don't charge companies to participate. While the 
SD Times 100 does welcome nominations from readers (and most of 
them do come from software makers and their publicists), the awards 
themselves are judged by the editors of SD Times. 

Our favorite category is "Influencers." That's the one that engenders 
the longest and most heated discussion between the judges. That's where 
we try to identify the companies that have had the broadest and deepest 
impact over the entire field of enterprise software development. 

In some cases, those Influencers are creating standards and industry 
specifications that we must conform to — or ignore at our peril. In some cas- 
es, the Influencer is building platforms that we're going to use — or compete 
against. In some cases, they are building tools that everyone wants to adopt, 
and which also set the bar higher for partners and competitors. 

While there are many companies or organizations that exert influ- 
ence — and they can be seen in the other SD Times 100 categories — they 
don't have the same overarching, category-defying influence as our 11 
Influencers. 

We hope you enjoy reading the 2009 SD Times 100. Tell us what you 
think of our picks: Where did we hit the bull's-eye? Who did we miss? 
Write us at feedback@bzmedia.com. I 



A Micro Focus, 
but what's the vision? 



As many readers discovered last 
month, part of Compuware 's prod- 
uct line is now property of Micro Focus, 
an English firm famed for its current 
dominant COBOL tools. Micro Focus 
also acquired the remains of what was 
once Borland. (Previously, 
CodeGear, the division of Bor- 
land that made IDEs — 
notably C++Builder, JBuilder 
and Delphi — had been sold to 
Embarcadero Technologies). 
The remains, which I'll discuss 
in a minute, were what Micro 
Focus purchased. 

The wheeling and dealing 
had all the feel of a three-team 
baseball transaction in which 
the teams acquire and unload players to 
make a stretch run. And, as in baseball, 
the nature of the trade showed compa- 
nies going in different directions in the 
same area. 

Let's start with Compuware, as it's the 
easiest. For a very long time, Com- 
puware has had two sets of product lines: 
one oriented to mainframes and enter- 
prise back-room operations, and one for 
Java and .NET developers. The latter 
products established the company's 
name at many IT sites due to their con- 
sistent high quality. 

But for all this acclaim, Compuware 
was never able to really establish its line 
of QA and quality-management prod- 
ucts: Optimal Trace, File-AID/CS, QA 
Director and other tools. In May of last 
year, the company announced a restruc- 
turing of its product offerings, dubbed 
"Compuware 2.0." Products that were 
neither market-leading nor core to its 
established lines were to be cut free; this 
sale was part of that process. 

Its purchase by Micro Focus is diffi- 
cult to explain. Micro Focus is exclusive- 
ly a COBOL and PL/I product vendor. 
Every tool feeds into that mission. Its 
acquisition of Borland's application life- 
cycle management tools is an attempt to 
provide a true end-to-end mainframe 
and enterprise product line. 

The problem is that the Borland tool 
chain consists of many links that don't 
interlock very well. They include Caliber 
(requirements), StarTeam (SCM), Silk 
(testing) and some project-management 
tools gathered under the "Team" 
moniker. Of these, the consensus is that 
the Silk testing tools, which were 
acquired from Segue, are the best and 
the only ones that could truly compete 
head-to-head with offerings from bigger 
companies. So, with this in mind, it's dif- 
ficult to see why Micro Focus would pay 
Compuware US$80 million for the tools 
that directly overlap the strongest part of 
the Borland suite. 



Integration Watch 




Micro Focus, a paradoxical name for 
a company that is enterprise-oriented, 
has made no clear announcement about 
its plans for the products. While we can 
expect that a smart or daring master 
plan lies behind these transactions, the 
company's past history is 
marked by a similar, earlier 
move that turned out very 
badly. I am referring to its 
1998 acquisition of Inter- 
solv, a company with a 
respected SCM product and 
a data integration line of 
business. 

The new company was 
called Merant. By 2001, the 
marriage had fallen apart so 
acrimoniously that the only solution was 
to split the merged pieces apart. Micro 
Focus was spun off to be the company it 
is now; Intersolv's data integration busi- 
ness was spun off as DataDirect Tech- 
nologies; and the SCM products were 
absorbed by Serena Software. The word 
on the street at the time was that the two 
parties' management fought from Day 1 
and were never able to work together. 
Presumably, Micro Focus' current man- 
agement has learned something from its 
recent history. But the proof will be in 
the pudding. 

Micro Focus' big advantage is that it 
has easy entry to thousands of large, 
enterprise sites via its COBOL products. 
Its challenge is that there is no com- 
pelling reason for those sites to adopt 
the tools that Borland could not turn 
into profit makers. Presumably, Micro 
Focus will have to integrate its COBOL 
and PL/I products with the Borland and 
Compuware product lines in order to 
have a compelling story. The question is 
whether it can do this well and, even 
more important, whether it can do so 
quickly. The company borrowed funds 
to make the pair of acquisitions, so it's 
under pressure to make the acquisition 
pay off soon. 

Because Micro Focus had probably 
reached maximum market penetration 
with its COBOL and PL/I tools, it had 
to do something to continue building 
revenue. Whether spending $155 mil- 
lion for these two purchases is the right 
thing is hard to tell. Micro Focus now 
enters a space with considerable com- 
petition that is well established, better 
financed, and in possession of integrat- 
ed product lines and trained sales peo- 
ple. To come out victorious, it will need 
great management and more than a lit- 
tle luck. I 

Andrew Binstock is the principal analyst 
at Pacific Data Works. Read his hlog at 
hinstock.hlogspot. com. 
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A GLOBAL ENVIRONMENTAL GROUP 

that targets e-waste (outdated computer 
and electronic equipment) called Basel 
Action Network (BAN) notified me last 
month that it had uncovered potential 
wrongdoing following a 
Humane Society-spon- 
sored e-waste recycling 
event in the Pittsburgh 
area. The events orga- 
nizers allegedly shipped 
the techno-trash over- 
seas in seven shipping 
containers instead of recycling it. BAN 
says that it tracked the waste to Hong 
Kong and South Africa, then notified the 
authorities in those countries. E-waste 
contains toxic elements, including cad- 
mium, mercury and lead. 

It is dismaying to me that there is no 
comprehensive nationwide program 
extant in the United States to dispose of 
toxic trash. Some strides have been 
made in e-waste collection, but now I 
am left wondering whether the right 
thing is ultimately being done. 

— David Worthington 

JEFF WILLIAMS, chair of the Open 
Web Application Security Project 
(OWASP), recently told me that the 
organization has been increasing its 
research reports. One of those research 
groups, the Intrinsic Security Working 
Group (ISWG), published a security 
analysis of Apache s Struts 2 framework 
for creating Java Web applications. 

ISWG examined what security fea- 
tures already exist in Struts 2 and what 
need to be created by the developer. "It 
shows that Struts has some stuff built 
into it, but there's an awful lot that you 
have to do yourself," Williams said. "It 
tells developers, 'Here's what you get. 
You can't just assume that because you 



wrote your app on top of Struts 2 that it's 
automatically secure. There's a lot you 
have to do yourself.' " 

Visit www.owasp.org for this report 
and for other reports on frameworks that 
you might be using. 

— Jeff Feinman 

GOOGLE'S I/O DEVELOPER CON- 
FERENCE, held last month, was the 
first such conference I've been to in 
years that treated developers like gold. 
Sun used to handle its Java folks with 
these spotless white gloves back during 
the dot-com era, and Microsoft used to 
do the same only a few years ago. But 
tight budgets at both companies have 
forced the frills to be funneled down 
into cheaper, less elaborate doses. 

But Google doesn't seem to mind 
spending money to woo developers. 
Indeed, it seems will- 
ing to spend as much 
as it feels is necessary 
to keep its coders hap- 
py. It's a good tactic to 
be sure, but one that 
inevitably will end in 
tears when Google decides 
to trim budgets three or four 
years down the line. 
For now, however, they seem to 
have a lock on the hip, cool new devel- 
oper conference award. 

— Alex Handy 

THERE OUGHTA BE A LAW that 
requires purveyors of technology — in 
this specific case, the phone/television/ 
Internet providers and cellular service 
providers — to list the true costs of what 
they're providing. 

I recently was moved to switch from 
the local cable television company 
to the phone/television/Internet service 



nft? 



provider with the promise of one low 
monthly fee for all the services. One of 
the features that appealed to me was the 
ability to record a show in one room of 
the house and view it in any other room 
where you have a TV with a set-top box. 
It's not until you actually try to do this 
that you find out that ALL the set-top 
boxes have to be top-of-the-line offer- 
ings. This would raise the cost of my ser- 
vice by about US$65 per month. 

And then I had to get the unlimited 
text messaging package at about anoth- 
er $45 per month after learning the 
hard way that it was more cost-effective 
than paying for individual text messages 
when my wife and children send 
literally thousands of texts per month. 
Also recently, my 15-year-old daughter 
wouldn't stop "hocking mir a chinik" (a 
lovely Yiddish expression meaning she 
was giving me headache by asking so 
many times already) about getting a 
BlackBerry. It seems they're all the rage 
in high school now. And, it was on sale 
for a mere $79.99. 

I learned that the price required a 
mail-in-rebate form (not a big deal), and 
also required the activation of data ser- 
vices at the cost of about $30 per month. 
I also had to purchase the accompanying 
package that included a 
Bluetooth headset, an 
upgraded memory card 
for photos and video, and 
multi-colored covers, so 
the look of the phone 
could change to reflect my daughter's 
ever-changing mood (happy when we're 
getting her something; not so much 
when we're not). That was a one-time 
charge of around $75. 

All this, and my money's on her losing 
the damn thing, or dropping it into a 
puddle and ruining the SIM card, by the 
end of the week. Can't someone out 
there cut me a break??? 

— David Rubinstein 




'High-piracy' countries push 
global software piracy rate up 
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In 2008, the rate of software piracy dropped in 57 countries and rose in another 17, according to a survey 
conducted by software industry consortium Business Software Alliance. BSA claimed that worldwide, 
the software piracy rate rose from 38% to 41% because PC shipments grew the fastest in "high-piracy" 
countries like China and India. The study was conducted by IDC. Above are piracy rates by region in the year 2008. 
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ASP.NET MVC may have a clunky 
name, but it's a great technology. 
The official line from Microsoft is that 
ASP.NET MVC is an alternative, not a 
replacement, for ASP.NET Web Forms, 
but I don't expect to use Web Forms as 
the technology for any new projects 
going forward. 

I've argued that "stuff in the 
right place" may be the defin- 
ing characteristic of good soft- 
ware. What I like the most 
about ASP.NET MVC is that it 
creates a nice scaffolding for 
business Web applications. To 
be sure, the Model- View-Con- 
troller design pattern boasts a 
purebred heritage going back 
to Smalltalk and is, probably, 
the most well-known pattern 
in object-oriented programming (at least 
by name if not by structural detail). 

ASP.NET MVC may put Smalltalk on 
its family crest, but it does so by way of 
Ruby on Rails. Rails has been a trailblazer 
and has become my preferred technology 
for Web development. The trouble with 
Rails is that Ruby developers have been 
hard to find, and corporate clients are 
often resistant to introducing the Ruby 
technology stack alongside their existing 
.NET or Java stacks. 

In contrast, a client who had nixed 
Rails for an upcoming project approved 
ASP.NET MVC without even a blip of 
hesitation. The Microsoft brand still 
means a lot. 

When a new ASP.NET MVC project 
is created, six different folders are gen- 
erated, with names like App_Data, Con- 
trollers, Views, etc. If you generate a 
Test project (which you ought to do), 
your "Project" window will end up being 
fairly crowded. I have to acknowledge 
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MVC wins MVP 



the school of thought that equates "ease" 
with "fewer files," and I can imagine a 
world where we (unfortunately) see 
newer programmers avoiding ASP.NET 
MVC because of its inherent complexity. 
In truth, navigating an ASP.NET MVC 
application is less complicated than navi- 
gating in most business applications. I 
have a client whose codebase 
is so bad that grepping from 
the root directory is universally 
seen as the fastest way to find a 
function definition. Even 
though that codebase is admit- 
tedly worse than normal, it all 
boils down to "a place to keep 
^f f your stuff," and ASP.NET 

MVC encourages a set of 
structural conventions that aid 
the placement of code. 
Additionally, the compile-time type 
information that you get with C# or VB 
allows Visual Studio to shine when it 
comes to navigation and code completion. 
I'm not going to turn in my membership 
card to the Ruby fan club, but as a team 
leader, I see ASP.NET MVC and C# as a 
better match for many teams. 

The fundamental principle of MVC is 
"separation of concerns," a term familiar 
in software design and unfortunately 
rare in Web applications. The Model is 
the business domain, the View is the 
Web page, and the Controller is the 
input channel. Of course, in a good 
application, there will be further divi- 
sions and blurry lines: The Model should 
abstract data storage, the View will prob- 
ably be configurable in some ways, and 
AJAX functionality doesn't quite divvy 
up properly. The better the separation of 
concerns and the more logical the "piles 
of stuff," the easier the application is to 
evolve, maintain and test. 



The Model is the place for business 
rules and the vast majority of data access. 
ASP.NET MVC uses LINQ-to-SQL for 
its storage model, which maps the expres- 
sive power of Language-Integrated Query 
to, well, SQL. My personal wish list for 
ASP.NET MVC might include built-in 
support for LINQ-to-NHibernate, a more 
flexible object-relational mapper, but I 
think LINQ-to-SQL is already a signifi- 
cant win over traditional data-access 
techniques. (Using N Hibernate with 
ASP.NET MVC seems to be fairly com- 
mon, but it's not supported directly.) 

My repeated use of "simplifies" in 
my description needs to be taken in the 
context of real-world development, 
which is inherently hard stuff. ASP.NET 
MVC is complex and has aspects, such 
as request routing and LINQ-to-SQL, 
that are going to be difficult to just mud- 
dle through. There are lots of Web 
resources and at least one good book, 
Wrox's "Professional ASP.NET MVC 
1.0," by a who's who of heavy hitters: 
Rob Conery, Scott Hanselman, Phil 
Haack and Scott Guthrie. 

Poor luck has it that the evolution of 
ASP.NET MVC 1.0 has been out of sync 
with the beta release of Visual Studio 
2010, and for now you can't investigate 
the two. Hopefully, this is a temporary 
glitch and the framework will be in the 
release candidate of VS 2010. Meanwhile, 
you can use the Microsoft Web Platform 
Installer to get ASP.NET MVC into Visu- 
al Studio 2008, and I suggest you do. This 
is the best framework for developing Web 
applications to come out of Microsoft, and 
I recommend it for new development. I 

Larry O'Brien is a technology consul- 
tant, analyst and writer. Read his hlog at 
www. knowing, net. 



business Briefs 




Hewlett-Packard and Microsoft have announced a four-year 
agreement around communications technologies. As part of the 
agreement, the two companies will form joint teams to collaborate 
on product and service development across Microsoft Office 
SharePoint Server, Microsoft Exchange Server and Microsoft 
Office Communications Server, as well as HP ProCurve networking 
products. They will invest US$180 million in product development 
and services along with joint sales and marketing . . . Enterprise 
C++ component and tool provider Rogue Wave Software has 
acquired analytics software company Visual Numerics. The Hous- 
ton-based Visual Numerics has two main product lines: the IMSL 
Numerical Libraries for mathematical and statistical analysis; and 
the PV-WAVE visual data analysis development environment. 
Rogue Wave executives said the acquisition of Visual Numerics 
brings advanced data analysis to Rogue Wave's software develop- 
ment tools, components and frameworks. 

EARNINGS: Hewlett-Packard announced financial results for its 
second fiscal quarter ended April 30, with net revenues of US$27.4 



billion, down 3% from the same quarter a year earlier. GAAP net 
earnings for the quarter were $1.7 billion, compared to $2.1 billion 
in the same quarter a year before. Revenue from HP's software 
unit declined 15% to $880 million, and operating profit from soft- 
ware was $157 million, up from $104 million in the prior-year peri- 
od .. . Business integration and RIA company Magic Software 
reported total revenues of US$13.8 million in its first quarter 2009, 
a decrease of 9% compared to $15.1 million in the first quarter of 
2008. Net income totaled $0.7 million, compared to $0.1 million in 
the first quarter of 2008, while operating income amounted to 
$0.7 million, compared to a loss of $0.1 million recorded in the 
same period of 2008 . . . Novell reported net revenues of US$216 
million for its second 2009 fiscal quarter ended April 30. That fig- 
ure was lower than net revenues of $236 million for the second fis- 
cal quarter of 2008. Net income in the 2009 quarter was $16 mil- 
lion, compared to net income of $6 million for same quarter a year 
earlier. Novell reported $37 million of revenue from its Linux plat- 
form, up 25% compared to the product revenue from Linux from 
the same period last year. I 



Events Calendar 



HP Software Universe 


June 16-18 


Las Vegas 




HEWLETT-PACKARD 




www.hpsoftwareuniverse2009.com 




eBay/PayPal 


June 16-18 


Developers Conference 




San Jose 




EBAY 




ebay.com/devcon 




iPhone Developer Summit June 22 


New York 




SYS-CON 




www.iphonedevsummit.com 




SOA World 


June 22-23 


Conference & Expo 




New York 




SYS-CON 




www.soaworld2009.com 




AJAXWorld RIA 


June 22-23 


Conference & Expo 




New York 




SYS-CON 




ajaxworld.com 




SPTechCon Boston 


June 22-24 


Boston 




BZ MEDIA 




sptechcon.com 




Velocity 


June 22-24 


San Jose 




O'REILLY MEDIA 




en.oreilly.com/velocity2009 




Microsoft Worldwide 


July 13-16 


Partner Conference 




New Orleans 




MICROSOFT 




partner.microsoft.com/40018508 





0SC0N July 20-24 

(Open Source Convention) 

San Jose 
O'REILLY MEDIA 

en.oreilly.com/oscon2009 



ACM SIGGRAPH 

New Orleans 
ACM SIGGRAPH 

www.siggraph.org/s2009 



August 3-7 



OpenSource World 
(formerly LinuxWorld) 

San Francisco 
IDG WORLD EXPO 

www.linuxworldexpo.com 



August 12-13 



SHARE 

Denver 
SHARE 

www.share.org 



August 23-28 



Agile 2009 

Chicago 
AGILEALLIANCE 

agile2009.agilealliance.org 



August 24-28 



VMworld 

San Francisco 
VMWARE 

www.vmworld.com 



August 31-Sept. 3 



Red Hat Summit Sept. 1-4 

SJBoss World 

Chicago 

RED HAT/JB0SS 

www.redhat.com/promo/summit/2009 

For a more complete calendar of U.S. software 
development events, see www.sdtimes.com/calendar. 
Information is subject to change. Send news about 
upcoming events to events@bzmedia.com. 
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Get the richest set of controls in one great suite. 
Studio Enterprise 2009 will amaze you with 
enhanced performance and presentation. 

NEW Studio for Silverlight 

• Add style to your Ul with built-in support for the most popular 
Microsoft Silverlight Toolkit themes 

• Create graphical navigation with 3D effects using the new 
CI CoverFlow control 

• Import and export RTF files with CI RichTextBox 

• Get ahead of the pack with access to the best resources, including 
40+ samples with source code for quick learning & online forums 

NEWStudioforASP.NET 

• Experience more interaction on the client-side with new 
lightweight, high-performance controls 

• Create themed and animated apps using dozens of built-in 
styles & effects 

• Eliminate the learning curve with new CIGridView control that 
mimics the Microsoft ASP.NET GridView control with added 
features like row filtering, virtual scrolling & more 

NEW Studio for iPhone 

• Build iPhone apps using ASP.NET 

• Give end-users a familiar experience across Web sites while taking 
advantage of the iPhone's unique interface 



Component One* 

Studio 
Enterprise 



GET STARTED TODAY • DOWNLOAD YOUR FREE TRI/ 



XapOptimizer 






ce the size of XAP 
files by up to * 

TRY IT FREE ONLINE @ 
labs.componentone.com 
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© 1 987-2009 ComponentOne. All rights 
reserved. iPhone and iPod are trademarks of 
Apple Inc. All other product and brand names are 
trademarks and/or registered trademarks of their 
respective holders. 
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Advanced Digital Dashboards Require 
Advanced Data Visualization 
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Dund 

Data Visualization 




as 



Fully Optimized For Visual Studio 2008! 

With new releases always in the pipe - including exciting .NET add-ons like our new Silverlight extension - Dundas gives you even more reasons to 
build effective custom dashboard solutions. 

As the leader in data visualization solutions for .NET,SharePoint 2007 and SQL Server Reporting Services 2005 & 2008, Dundas offers the latest 
award-winning chart, gauge, map and calendar technologies. Now you know why Fortune 500 companies around the globe trust Dundas to create 
sophisticated and visually compelling dashboard components. 

To see for yourself how Dundas products can improve your applications, download full evaluation copies of Dundas Chart, Gauge, Map and 
Calendar from www.dundas.com/downloads . 
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Microsoft, SharePoint, SQL Server and Visual Studio are registered trademarks of Microsoft Corporation in the United States and/or other countries 
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